2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-4511 | — | — | 82.7% | Jul 22, 2014 | Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in ... |
| CVE-2014-4326 | — | — | 3.3% | Jul 22, 2014 | Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a cra... |
| CVE-2014-2385 | — | — | 4.5% | Jul 22, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow loca... |
| CVE-2014-5018 | — | — | 1.5% | Jul 21, 2014 | Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allo... |
| CVE-2014-5017 | — | — | 1.9% | Jul 21, 2014 | SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 14... |
| CVE-2014-5016 | — | — | 1.5% | Jul 21, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject ar... |
| CVE-2014-4960 | — | — | 2.3% | Jul 21, 2014 | Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x throu... |
| CVE-2014-4734 | — | — | 1.9% | Jul 21, 2014 | Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to ... |
| CVE-2014-4987 | — | — | 1.3% | Jul 20, 2014 | server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to b... |
| CVE-2014-4986 | — | — | 1.6% | Jul 20, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.1, 4.1.x before... |
| CVE-2014-4955 | — | — | 1.5% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the PMA_TRI_getRowForList function in libraries/rte/rte_list.lib.php in phpM... |
| CVE-2014-4954 | — | — | 1.5% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in php... |
| CVE-2014-4342 | — | — | 6.5% | Jul 20, 2014 | MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffe... |
| CVE-2014-4341 | — | — | 7.1% | Jul 20, 2014 | MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and appli... |
| CVE-2014-3894 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote a... |
| CVE-2014-3892 | — | — | 1.1% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Nexa Meridian before 2014 allows remote attackers to inject arbitrary web sc... |
| CVE-2014-3886 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attac... |
| CVE-2014-3885 | — | — | 0.9% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary we... |
| CVE-2014-3884 | — | — | 1.4% | Jul 20, 2014 | Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script ... |
| CVE-2014-3523 | — | — | 16.4% | Jul 20, 2014 | Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x be... |
| CVE-2014-3162 | — | — | 1.0% | Jul 20, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service ... |
| CVE-2014-3161 | — | — | 0.9% | Jul 20, 2014 | The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome be... |
| CVE-2014-3160 | — | — | 1.3% | Jul 20, 2014 | The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.... |
| CVE-2014-3159 | — | — | 0.9% | Jul 20, 2014 | The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegat... |
| CVE-2014-1999 | — | — | 2.7% | Jul 20, 2014 | The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitr... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now